1. Zero Customer Data Training
Your data is strictly yours. Operon does not train foundational AI models on your workspace goals, uploaded artifacts, custom prompt instructions, or tool execution history.
- All upstream model integrations (OpenAI, Anthropic, Google Vertex AI, Groq) are configured via enterprise zero-data-retention APIs where customer inputs are never used to train public models.
- When you utilize Bring Your Own Key (BYOK), requests execute under your direct organization agreement with each model provider.
2. Encrypted BYOK Vault Architecture
When you add proprietary API keys (OpenAI, Anthropic, Google Gemini, Groq, or custom REST secrets) to Operon, they are never stored in plaintext.
- Two-Tier Envelope Encryption: Secrets are encrypted using individual Data Encryption Keys (DEKs) wrapped by an AES-256 Fernet Master Key.
- Ephemeral Memory Ingestion: Keys are decrypted exclusively in worker RAM during execution turns and immediately flushed upon step completion.
- Zero Log Exposure: Automated log scrubbers sanitize all API keys, PATs, and bearer tokens before payloads enter application logs or Sentry telemetry.
3. Multi-Tenant Data Isolation
Operon employs strict row-level security and tenant-scoped schema policies. Every database query, vector semantic search in pgvector, artifact file retrieval, and WebSocket streaming channel is bounded to verified organization IDs issued by Clerk JWT authentication.
4. Sandboxed Tool & SQL Guardrails
Autonomous agents operate within defense-in-depth boundaries to prevent unauthorized operations:
- Read-Only SQL AST Sanitization: Database query tools inspect SQL syntax trees to enforce read-only (
SELECT) operations, rejectingDROP,UPDATE,DELETE, orALTERstatements. - Human-In-The-Loop (HITL) Interrupts: High-risk operations (such as sending emails, deleting repositories, or public publishing) automatically pause execution and require explicit approval in your Inbox.
- Workspace Sandboxing: File operations are sandboxed within tenant-isolated storage buckets with strict path traversal prevention.
5. Prompt Injection Defense & Input Screening
Operon deploys continuous prompt guardrails to detect and mitigate indirect prompt injections from untrusted web pages, emails, or third-party API outputs before they can influence agent planning decisions.
6. SOC2, ISO & Enterprise Governance
Operon adheres to SOC2 Type II trust service principles covering Security, Availability, and Confidentiality. We maintain immutable audit logs (AuditEvent) capturing actor IDs, execution durations, IP addresses, and resource access for enterprise compliance.
Download our compliance documentation or request a custom DPA on our Data Processing Agreement page.
7. Responsible Vulnerability Disclosures
We welcome collaboration with security researchers. If you discover a potential vulnerability in Operon, please report it responsibly to security@operon.ai. We commit to acknowledging receipt within 24 hours and providing remediation updates.